1. Intriguing properties of neural network;Szegedy
2. Adversarial Examples: Attacks and Defenses for Deep Learning
3. Delving into transferable adversarial examples and black-box attacks;Liu
4. Transferability in machine learning: from phenomena to black-box attacks using adversarial samples;Papernot,2016
5. Perturbing across the feature hierarchy to improve standard and strict black-box attack transferability;Inkawhich